Answered: [Security threat] tags are not sanitized in extra question field

Post date: 2020-07-01 00:44:51
Views: 172

Hey q2apro, I think you are testing the default q_view_extra($q_view); function.

The default function is still safe. But if you pull the content from the databse, it's not safe.

First, look! The script is stored in database.

database

Second, if create a function to pull that content form the datase:

public function q_item_extra($q_item)
{
$postidz = $q_item'raw']'postid'];
$extra = qa_db_read_one_value(qa_db_query_sub(
       'SELECT content FROM ^postmetas WHERE title="qa_q_extra" AND postid=#',
        $postidz
   ), true);
 
 //$extra = $q_item'extra']'content'];
 
        $this->output('My info:'.$extra);   
   
}

Here's the result:

test

I hope you'll get my point.

Please click Here to read the full story.
 
Other Top and Latest Questions:
London's answer to Wall Street gains momentum as major firms sign on
The New York Times sues Perplexity, alleging copyright infringement
Tokenized stocks offer new opportunities for investors, but carry unique risks
Apple announces departure of general counsel and policy chief
Putin says Russia is willing to supply 'uninterrupted' fuel to India, as U.S. pressures New Delhi to cut back
4 'good enough' financial moves to reach your goals with 'less time and hassle,' from a money expert
Musk denies $800 billion SpaceX valuation reports
Gemini success to drive Alphabet shares to $400, cause OpenAI to cut capex, says Pivotal
Judge finalizes remedies in Google antitrust case
Married millennials, here comes the crypto divorce cliff